Togoder security

npm package security report

eth-json-rpc-filters npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 6.0.1 Files reviewed 9 Size 20.3 KB Scanned

Summary

Togoder Security scanned the npm package eth-json-rpc-filters@6.0.1 on Oct 4, 2026. An AI review of 9 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Insecure randomness

NPS-4C48B4C836D5

The function unsafeRandomBytes explicitly uses Math.random() to generate random bytes. Math.random() is not cryptographically secure and its output is predictable. If this function is used for security-sensitive purposes such as generating private keys, nonces, or session tokens, it could lead to vulnerabilities. The naming 'unsafeRandomBytes' suggests awareness, but the presence of such a function in a utility module may encourage misuse.

hexUtils.js:45
medium

Weak random number generation for subscription IDs

NPS-C2AFCDE5B054

The code uses unsafeRandomBytes(16) to generate subscription IDs. If unsafeRandomBytes is not cryptographically secure (e.g., uses Math.random or a weak PRNG), it could allow attackers to predict or brute-force subscription IDs, leading to unauthorized access to subscription data or denial of service. The name 'unsafe' suggests it may intentionally use a non-cryptographic source.

subscriptionManager.js:33
low

Potential unhandled promise rejection / async destroy calls

NPS-B1A11E7315A3

The destroy function calls subscriptions[id].destroy() without awaiting or catching errors. While not a direct security issue, it could lead to resource leaks or unhandled rejections if destroy fails. More importantly, the asynchronous destroy in createSubNewHeads removes a listener, but if the blockTracker emits events during the async gap, it might cause unexpected behavior.

subscriptionManager.js:115

Files reviewed

FileVerdictWhat the reviewer saw
hexUtils.js medium The code provides utility functions for hex and block reference manipulation, but includes an insecure random byte generator using Math.random(), which is cryptographically weak and could be dangerous if misused for security purposes.
subscriptionManager.js medium The code appears to be a legitimate Ethereum subscription manager, but uses a function named 'unsafeRandomBytes' for generating subscription IDs, which may introduce predictability risks.
base-filter-history.js safe Cleared by Jev triage; no further analysis needed
base-filter.js safe Cleared by Jev triage; no further analysis needed
block-filter.js safe No malicious patterns detected
getBlocksForRange.js safe No malicious patterns detected; the code performs standard Ethereum JSON-RPC block queries with retry logic and no exfiltration, credential access, obfuscation, or suspicious system operations.
index.js safe No malicious patterns detected; the code is a legitimate Ethereum JSON-RPC filter middleware implementation.
log-filter.js safe No malicious patterns detected
tx-filter.js safe No malicious patterns detected

Scanned versions of eth-json-rpc-filters

VersionVerdictFilesScanned
6.0.1 Needs review 9 Oct 4, 2026

Frequently asked questions

Is eth-json-rpc-filters safe to use?

No confirmed malware was found in eth-json-rpc-filters@6.0.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does eth-json-rpc-filters contain malware?

No malware was identified in eth-json-rpc-filters@6.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was eth-json-rpc-filters checked?

Togoder Security downloaded the published npm package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan eth-json-rpc-filters together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eth-json-rpc-filters@6.0.1, cost nothing.

Related security reports